΢ÈíÐû²¼´øÍâ¸üР£¬ÐÞ¸´Windows 10ÖеĴúÂëÖ´ÐÐÎó²î£»ÐÂÐͶñÒâÈí¼þGluptebaÕë¶ÔWindowsϵͳ

Ðû²¼Ê±¼ä 2020-07-01

1.΢ÈíÐû²¼´øÍâ¸üР£¬ÐÞ¸´Windows 10ÖеĴúÂëÖ´ÐÐÎó²î


Ò«ÊÀÓéÀÖ-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ¡£


MicrosoftÐû²¼ÁËÁ½¸ö´øÍâÇå¾²¸üР£¬ÒÔÐÞ¸´Ô¶³Ì´úÂëÖ´ÐÐÎó²î¡£ÕâÁ½¸öÎó²î±»×·×ÙΪCVE-2020-1425ºÍCVE-2020-1457 £¬Ó°ÏìÁ˶à¸öWindows 10ºÍWindows Server°æ±¾ £¬Æä¾ùÊÇÓÉMicrosoft Windows Codecs¿â´¦Öóͷ£ÄÚ´æÖй¤¾ßµÄ·½·¨ÒýÆðµÄ¡£ºÚ¿ÍÀÖ³ÉʹÓÃCVE-2020-1425ºó £¬¿ÉÒÔ½øÒ»²½ÆÆËðÓû§ÏµÍ³ £¬¶øÀÖ³ÉʹÓÃCVE-2020-1457Ôò¿ÉÔÚÄ¿µÄϵͳÉÏÖ´ÐÐí§Òâ´úÂ롣΢ÈíÌåÏÖ £¬Õë¶ÔÕâÁ½¸öÎó²îûÓлº½â²½·¥ £¬¸üн«ÓÉMicrosoft Store×Ô¶¯×°ÖþÙÐС£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/microsoft-releases-oob-security-updates-for-windows-10-rce-bugs/


2.Sophos·¢Ã÷ÐÂÐͶñÒâÈí¼þGlupteba £¬Õë¶ÔWindowsϵͳ


Ò«ÊÀÓéÀÖ-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ¡£


Sophos LabsµÄÑо¿Ö°Ô±ÔÚÒ°Íâ·¢Ã÷ÁËÒ»ÖÖÕë¶ÔWindowsϵͳµÄÐÂÐͶñÒâÈí¼þGlupteba £¬Ëü¿ÉÔÚÄ¿µÄPCÖпª·¢ºóÃÅ £¬²¢½«ÆäѬȾΪ½©Ê¬ÍøÂçµÄÒ»²¿·Ö¡£Ñо¿Ö°Ô±ÌåÏÖ £¬Glupteba¾ßÓÐÒþ²ØÐÔ £¬Ëü¿ÉÒÔDZÔÚÔÚ¶ñÒâÈí¼þɾ³ý³ÌÐòÖÐ £¬²¢Ê¹ÓÃÆäÏÂÔØ²¢Ö´ÐÐÓÐÓÃÔØºÉ¡£Gluptebaͨ¹ýÌáȨÀ´Ö´ÐÐrootkit £¬Ëðº¦Ä¿µÄ×°±¸µÄÇå¾²ÐÔ¡£³ý´ËÖ®Íâ £¬Glupteba½«ÊÜѬȾµÄÅÌËã»úת±äΪ½©Ê¬ÍøÂçºó £¬»¹»áʹÓøÃÊܺ¦×°±¸É¨ÃèÆäËûÒ×Êܹ¥»÷µÄ×°±¸ £¬²¢Ê¹ÓÃÎó²îEternalBlue £¬ÔÚÍøÂçÉϺáÏòÈö²¥¡£


Ô­ÎÄÁ´½Ó£º

https://latesthackingnews.com/2020/06/29/sneaky-glupteba-malware-creates-backdoor-in-windows-pcs/


3.ºÚ¿ÍÔÚ°µÍø³öÊÛ14¼Ò¹«Ë¾µÄÊý¾Ý¿â £¬Áè¼Ý1.3ÒÚÌõÊý¾Ý


Ò«ÊÀÓéÀÖ-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ¡£


ºÚ¿ÍÔÚ°µÍø³öÊÛ°üÀ¨14¼Ò¹«Ë¾Óû§¼Í¼µÄÊý¾Ý¿â £¬²¢Éù³ÆÕâЩ¹«Ë¾¾ùÊÇÔÚ2020Äê±»ºÚ¿ÍÈëÇֵġ£ÕâЩÊý¾Ý¿â×ܹ²°üÀ¨132957579ÌõÓû§¼Í¼ £¬Ö»¹Üÿ¸öÊý¾Ý¿âÖеÄÐÅÏ¢²î±ð £¬¿ÉÊÇËüÃǶ¼°üÀ¨Óû§ÃûºÍ¹þÏ£ÃÜÂë¡£14¼Ò¹«Ë¾»®·ÖΪDarkThrone¡¢Efun¡¢Fluke¡¢Footters¡¢HomeChef¡¢JamesDelivery¡¢KitchHike¡¢KreditPlus¡¢Minted¡¢Playwings¡¢Revelo¡¢Tokopedia¡¢YoteprestoºÍZoosk £¬ÆäÖÐÓÐ4¼Ò¹«Ë¾µÄÊý¾Ý¿âÔÚÒÑÍù¾Í±»Ð¹Â¶¹ý¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/seller-floods-hacker-forum-with-data-stolen-from-14-companies/


4.¼ÓÖÝ´óѧ¾É½ðɽ·ÖУÒÑÏòNetwalkerÖ§¸¶114ÍòÃÀÔªÊê½ð


Ò«ÊÀÓéÀÖ-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ¡£


¼ÓÖÝ´óѧ¾É½ðɽ·ÖУ£¨UCSF£©ÌåÏÖ £¬ÆäÒÑÏòÀÕË÷Èí¼þ×éÖ¯NetwalkerÖ§¸¶ÁË114ÍòÃÀÔªµÄÊê½ð¡£NetwalkerÓÚ6ÔÂ3ÈÕÔÚÆäÊý¾Ý×ßÂ©ÍøÕ¾ÉÏÐû²¼ÐÂÎÅ £¬Éù³ÆËüÒÑÈëÇÖÁËUCSFµÄÍøÂ粢͵ȡÁËÎļþ £¬°üÀ¨´øÓÐÉç»áÇå¾²ºÅÂëµÄѧÉúÉêÇë¡¢°üÀ¨Ô±¹¤ÐÅÏ¢µÄÎļþ¼Ð £¬Ò½Ñ§Ñо¿ºÍ²ÆÎñÐÅÏ¢µÈ¡£UCSFÌåÏÖ £¬ÆäITÖ°Ô±ÔÚ6ÔÂ1ÈÕ¼ì²âµ½Á˸ÃÊÂÎñ £¬²¢¸ôÀëÁËҽѧԺÄڵöITϵͳ £¬µ«²¿·ÖҽѧԺϵͳµÄÊý¾ÝÕվɱ»¼ÓÃÜ¡£ÓÉÓÚ±»¼ÓÃܵÄÊý¾Ý¶Ô¸Ã´óѧµÄѧÊõÊÂÇéÀ´ËµºÜÊÇÖ÷Òª £¬Òò´ËÆä¾öÒéÖ§¸¶Êê½ðÒÔ»ñµÃ½âÃܹ¤¾ß¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/uc-san-francisco-pays-114-million-for-ransomware-decryptor/


5.ESETͳ¼Æ £¬ÒßÇéʱ´úRDPƽ¾ùÌìÌìÔâµ½Áè¼Ý10Íò´Î¹¥»÷


Ò«ÊÀÓéÀÖ-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ¡£


ESETͳ¼Æ £¬ÒßÇéʱ´úºÚ¿Í¶ÔWindowsÔ¶³Ì×ÀÃæ·þÎñµÄ¹¥»÷´ÎÊýÏÕЩÔöÌíÁËÒ»±¶ £¬Æ½¾ùÌìÌìÁè¼Ý10Íò´Î¡£ÍøÂçÇå¾²¹«Ë¾ESET×Ô2019Äê12ÔÂ1ÈÕÒÔÀ´¼Í¼µÄÒ£²âÊý¾ÝÏÔʾ £¬ÌìÌì¶ÔRDPµÄ±©Á¦¹¥»÷´ÎÊý¼±¾çÔöÌí¡£´Ó2019Äê12Ôµ½2020Äê2Ô £¬ÌìÌì»á±¬·¢40000µ½70000´Î¹¥»÷¡£×Ô2Ô·ݹ¥»÷´ÎÊý×îÏÈÉÏÉý £¬ÓÉÖðÈÕ80000´Î×îÏÈ £¬µ½4ÔºÍ5Ô·ݵִïÎÈ¹Ì £¬Æ½¾ùÖðÈÕÁè¼Ý100000´Î¹¥»÷¡£Æ¾Ö¤ESETµÄÊÓ²ì £¬ÕâЩ¹¥»÷´ó¶àÀ´×ÔÃÀ¹ú¡¢Öйú¡¢¶íÂÞ˹¡¢µÂ¹úºÍ·¨¹úµÄIPµØÖ· £¬¶øÄ¿µÄIPµØÖ·Î»ÓÚ¶íÂÞ˹¡¢µÂ¹ú¡¢°ÍÎ÷ºÍÐÙÑÀÀû¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/over-100k-daily-brute-force-attacks-on-rdp-in-pandemic-lockdown/


6.Abnormal·¢Ã÷ £¬Õë¶Ô·¢Æ±»ò¸¶¿îڲƭµÄBEC¹¥»÷ÔöÌí200£¥


Ò«ÊÀÓéÀÖ-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ¡£


Abnormal Security·¢Ã÷ £¬´Ó2020Äê4Ôµ½2020Äê5Ô £¬Õë¶Ô·¢Æ±»ò¸¶¿îڲƭµÄBEC¹¥»÷ÒÑÔöÌíÁË200£¥¡£¹¥»÷Õßͨ¹ýð³ä¹©Ó¦ÉÌ»ò¿Í»§ £¬Í¨¹ýʹÓõç»ãڲƭ»òÐ®ÖÆ¹©Ó¦É̶Ի°µÈÖØ¶¨ÏòÕ½ÂÔÀ´ÇÔÈ¡×ʽð¡£ÓëÆäËûÀàÐ͵ÄBEC¹¥»÷Ïà±È £¬ÕâЩÀàÐ͵Ĺ¥»÷ËùÉæ¼°µÄ½ð¶îͨ³£Òª´óµÃ¶à £¬ÓÉÓÚËüÃÇÕë¶ÔµÄÊÇÆóÒµ¶ÔÆóÒµµÄÉúÒâ¡£Abnormalͨ¹ý¸ú×ÙÕâÀ๥»÷ £¬·¢Ã÷ÿÖÜÆ½¾ùµÄ¹¥»÷Á¿Ìá¸ß200£¥ £¬Ôâµ½´ËÀ๥»÷µÄ×éÖ¯ÊýÄ¿ÔöÌíÁË36£¥¡£


Ô­ÎÄÁ´½Ó£º

https://www.helpnetsecurity.com/2020/06/30/payment-fraud-bec-attacks/